Cybersecurity professional specializing in Microsoft Defender solutions. Proven expertise in troubleshooting and configuring security systems, enhancing team performance, and driving customer satisfaction. Adept at managing complex issues and fostering knowledge growth among engineers, ensuring seamless operations and effective security measures.
Working for Microsoft Security EPS, supporting customers with troubleshooting, managing, and consulting for Microsoft Defender Antivirus and Microsoft Defender for Endpoint.
Microsoft Defender Antivirus (MDAV): experienced in configuring, managing, and troubleshooting Microsoft Defender Antivirus and System Center Endpoint Protection (SCEP) Proficient in key features such as tamper protection, network protection, web protection, and exploit guard, skilled in ensuring AV is functioning correctly on endpoints, regularly updated, and free of errors to maintain optimal protection
Policy management: well-versed in deploying and managing Defender policies using Microsoft Intune (MEM), System Center Configuration Manager (SCCM), and Group Policy Objects (GPO)
Performance and issue troubleshooting: strong ability to diagnose system performance issues, such as CPU, memory, etc using tools such as Process Monitor and Windows Performance Analyzer
Microsoft Defender for Endpoint (MDE) and XDR: proficient in onboarding and offboarding endpoints, configuring proxies, and ensuring smooth integration and operation of Microsoft Defender for Endpoint and Defender XDR Skilled in using MDE Client Analyzer to troubleshoot and resolve connectivity issues
Threat Detection & Response:
Experienced in investigating alerts and incidents in the MDE portal, determining true or false positives Familiar with creating and managing Indicators of Compromise (IOCs), Web Content Filtering (WCF) policies, and verifying their effectiveness on endpoints
Vulnerability Management:
Hands-on experience with Microsoft Defender Vulnerability Management Involved in analyzing security recommendations, addressing exposed devices, and improving overall secure and exposure scores Skilled in investigating and responding to CVEs and software vulnerabilities
Data Analysis & Investigation:
Use of Kusto Query Language (KQL) to retrieve and analyze endpoint data for in-depth investigations and reporting
Cross-Platform Integrations:
Expertise in integrating Microsoft security tools with platforms such as Azure Security Center (ASC), Microsoft Cloud App Security (MCAS), Microsoft Endpoint Manager (MEM), and various SIEM solutions